Avoid The Hack!

@avoidthehack
111 Followers
87 Following
1.7K Posts

An initiative promoting the intersection of internet #privacy and #cybersecurity for all users.

MOVED to infosec.exchange -> @avoidthehack

avoidthehackhttps://avoidthehack.com
Twitterhttps://twitter.com/avoidthehack
Ko-Fihttps://ko-fi.com/avoidthehack

How to share files and sensitive information securely

@bitwarden shows you how to use Bitwarden Send to share files and sensitive information in a more secure way.

In most cases, you should avoid sending sensitive information via email (even if not a file).

#opsec #cybersecurity #security

https://bitwarden.com/blog/how-to-share-files-and-sensitive-information-securely/

How to share files and sensitive information securely | Bitwarden Blog

Bitwarden makes it easy to securely share files and sensitive information with anyone using Bitwarden Send.

Bitwarden

Avoidthehack updates #private #browser Comparison Tool

- Added Mullvad @mullvadnet browser
- Added Comodo IceDragon
- Fixed image display issues on some #browsers
- Corrected existing information

#privacy #privacymatters #opensource

https://avoidthehack.com/util/browser-comparison

Browser Comparison Tool | Avoid the Hack (avoidthehack!)

This is an interactive table designed to easily compare features of various "privacy-focused" browsers.

Avoid the Hack (avoidthehack!)

CISA Adds Five Known #Vulnerabilities to Catalog

CVE-2023-32046 Microsoft Windows MSHTML Platform Privilege Escalation
CVE-2023-32049 Microsoft Windows Defender SmartScreen Security Feature Bypass
CVE-2023-35311 Microsoft Outlook Security Feature Bypass
CVE-2023-36874 Microsoft Windows Error Reporting Service Privilege Escalation
CVE-2022-31199 Netwrix Auditor Insecure Object Deserialization

#cybersecurity #infosec #security

https://www.cisa.gov/news-events/alerts/2023/07/11/cisa-adds-five-known-vulnerabilities-catalog

Microsoft today issued security updates to fix a whopping 130 flaws in Windows etc, including 4 zero-day vulnerabilities. MSFT issued an advisory for but did not patch a fifth zero-day that is being exploited by ransomware crooks reportedly working in support of Russian intelligence operations. Meanwhile, Apple issued and then pulled a patch for a zero-day flaw in iOS and macOS. The Apple flaw is fixed in iOS/iPadOS 16.5.1, macOS 13.4.1, and Safari 16.5.2.

#patchemifyougotem

https://krebsonsecurity.com/2023/07/apple-microsoft-patch-tuesday-july-2023-edition/

Apple & Microsoft Patch Tuesday, July 2023 Edition – Krebs on Security

Whoa. Sophos researchers just announced that they’ve uncovered 133 malicious drivers signed with legitimate digital certificates, and found 100 of of those 133 drivers were signed by Microsoft.

https://news.sophos.com/en-us/2023/07/11/microsoft-revokes-malicious-drivers-in-patch-tuesday-culling/

From the post:

"Today, Microsoft issued Security Advisory ADV230001 as part of their July Windows Update that addresses Sophos’ discovery of more than 100 malicious drivers that had been digitally signed by Microsoft and others, dating as far back as April 2021."

"They also released Knowledge Base article 5029033, which includes new, more detailed information on the technical measures Microsoft has taken to protect against these malicious signed drivers."

https://msrc.microsoft.com/update-guide/vulnerability/ADV230001

https://support.microsoft.com/help/5029033

Today's post about patches from Microsoft and Apple to quash zero-day bugs:

https://krebsonsecurity.com/2023/07/apple-microsoft-patch-tuesday-july-2023-edition/

I wrote recently about one of the bigger names in signing malware as a service:

https://krebsonsecurity.com/2023/06/ask-fitis-the-bear-real-crooks-sign-their-malware/

Microsoft Revokes Malicious Drivers in Patch Tuesday Culling

In December 2022, Microsoft published their monthly Windows Update packages that included an advisory about malicious drivers, signed by Microsoft and other code-signing authorities, that Sophos X-…

Sophos News

#Apple releases emergency #update to fix zero-day exploited in attacks

CVE-2023-37450 - code execution in the WebKit browser engine (which powers Safari).

#cybersecurity #infosec #security

https://www.bleepingcomputer.com/news/apple/apple-releases-emergency-update-to-fix-zero-day-exploited-in-attacks/

Apple releases emergency update to fix zero-day exploited in attacks

Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads.

BleepingComputer

#Google Changed Its #Privacy Policy: Does the Tech Giant Now Use All Your Data to Train Its AI?

From @Tutanota

Color me surprised. 🤫

#ai #privacymatters

https://tutanota.com/blog/google-trains-ai-with-your-data

Google Changed Its Privacy Policy: Does the Tech Giant Now Use All Your Data to Train Its AI?

Google has found a new way to make millions with your data: Training its own AI with the data you give Big Tech for free.

Tutanota

How to block emails on #Gmail, Outlook, Proton Mail, Yahoo Mail, and #Apple Mail

From @protonmail

#privacy #email #privacymatters

https://proton.me/blog/how-to-block-emails

How to block emails on Gmail, Outlook, Proton Mail, Yahoo Mail, and Apple Mail | Proton

Learn how to stop unwanted emails on Gmail, Outlook, Proton Mail, Yahoo Mail, Apple Mail, and Thunderbird and use aliases to hide you email.

Proton

New ‘Big Head’ ransomware displays fake Windows update alert

Suspected to be spreading primarily through *gasp* Malvertising.

During the encryption stage, this #ransomware displays a loading screen similar to a #windows update.

#cybersecurity #infosec #security

https://www.bleepingcomputer.com/news/security/new-big-head-ransomware-displays-fake-windows-update-alert/

New ‘Big Head’ ransomware displays fake Windows update alert

Security researchers have dissected a recently emerged ransomware strain named 'Big Head' that may be spreading through malvertising that promotes fake Windows updates and Microsoft Word installers.

BleepingComputer

How Threads’ #privacy policy compares to Twitter’s (and its rivals’)

#threads has abysmal privacy... just reading the list in this article is exhausting.

I fail to see how it is an "acceptable middleground" for users being introduced into the #fediverse (with the talk of ActivityPub integration.)

#privacymatters #mastodon

https://arstechnica.com/security/2023/07/how-threads-privacy-policy-compares-to-twitters-and-its-rivals/

How Threads’ privacy policy compares to Twitter’s (and its rivals’)

Here’s what is collected by Threads, as well as by Twitter, Bluesky, Mastodon, Spill, and Hive Social.

Ars Technica